May 5, 2001
RealAudio 0:42hr
Not archived
top
|
- Hacker
Attacks from China
- Whitehouse
(May 4th, 5-8AM and 1-2PM, shut down completely)
- CIA
(May 1st, 10-11AM, reduced to 8% efficiency)
- Starting
April 30 and ending May 7, 2001
- Internet
worm Lion is being used to install DDOS clients and to send password
back to PRC
- The
Anatomy of our Response to the Internet Threat (why it worked so well)
- Orchestrated
by SANS Institute
- SANS
stands for System Administration, Networking, and Security
- Internet
Storm Center Event Summary
- On
March 22, 2001, organizations that had not updated BIND (port
53) were rewarded with a worm called Lion
- Lion
send password files from infected machines to a site in
China
- Lion
installed a DDOS zombie on each machine
- Hundreds
of instrusion sensors sent their logs to sites in Cambridge,
Atlanta, Reston, and Indianapolis for aggregation
-
A man made electronic storm was sweeping the Internet.
- Port
53 probes went from 200 per day to 50,000 per day on March
22 for one region.
- SANS,
NIPC, and CERT got their first copy of Lion later that day and went
into action.
- Just
14 hours after the port 53 spike, 200, 000 warning letters were
sent advising them how to check for the worm and install BIND
patches.
- A
few hours later, UUNET (as directed by the FBI) took off line
the address that was collecting the password data.
- Lion
worm event demonstrated that the community acting together can respond
to a broad-based malicious attack using real time logs and advisories.
- Napster
Judge Utterly Frustrated
- US
District Judge Marilyn Hall Patel has strongly endorsed a series
of rulings
- Needs
clarification from court to enforce ruling
- Napster
users are too clever with name changes
- Record
companies need to police the naming game
- Dvorak
thinks that Record Industry has it all wrong
- Another
sharing technology BearShare.com doubled in size during March
- Digital
Signature Program TRM to the Rescue of Napster
- From
Washington Post, May 3th, 2001, Style (Section C)
- Sean
Ward, 20, of Alexandria, created TRM.
- Created
a method to create and test an MP3 Digital Signature for song ID
- Name
games will not longer work
- Copy
protected songs will simply not be posted to the main Napster index
- This
may actually save Napster and enable a new method for song distribution.
- Tech
Talk favors this approach
- Wireless
Security Standards in Turmoil
- 802.11b
security standard WEP (Wired
Equivalent Privacy Standard) is vulnerable
- Reported
by SANS
- Vendors
do not agree on same encryption method.
- Technology
may not be ready for prime time
- Other
Microsoft News
- Stratford
News
- Visited
Franklin
Middle School
- Talked to English Class of Mrs. Siemen about Careers
- Very
attentive group of students
- Dr.
Fred Ricci started as Dean of the Graduate Program at Stratford
University
- Dr.
Ricci was Dean of EE, Virginia Tech, in Northern Virgina for 12
years
- Most
recently he was with WinStar
- He
is managing the Masters Programs that Stratford will be starting
in September, pending approval by SCHEV
- He
is also putting together corporate training efforts in the area
of Wireless Telecommunications.
- We have
classes starting on May 29th
|